每個團隊的企業級安全性
由 Boomi 的創始人領導,我們知道安全性有多重要。 擁有數十年的經驗團隊,Guru 不眠不休地確保您的數據安全。
Guru 符合最高的安全標準
Soc 2 Type 2
PCI Compliant
GDPR Ready
EU - U.S. Privacy Framework
Guru complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Guru has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. Guru has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in our privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) Program, and to view our certification, please visit https://www.dataprivacyframework.gov/
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Guru commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU and UK individuals and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF should first contact Guru at: privacy@getguru.com.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Guru commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF to the International Centre for Dispute Resolution, an alternative dispute resolution provider based in New York, the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit https://go.adr.org/dpf_irm.html for more information or to file a complaint. The services of the International Centre for Dispute Resolution are provided at no cost to you
[See all details in our FAQ]
Microsoft SSPA
CA 隱私權法案
為什麼您可以信任 Guru 的 AI
您的數據始終在我們這裡安全。 我們的鐵箍保護無論內容來自何處,都可保障您的內容安全,使您能夠毫無疑慮地使用我們的 AI 驅動的企業搜索。
第三方 LLM 零數據保留
您的數據從未被用於訓練,也不會被第三方 LLM 保留
只有您擁有您的數據和內容
您團隊的所有內容和數據都是您的,而不是 Guru 的
基於角色的訪問控制
用戶只會看到他們已經有權限查看的內容
私有 AI 模型
您團隊的 AI 模型對您是唯一的,並基於您團隊的數據和互動在您的 Guru 實例中私下訓練
其他安全功能
認識 Wes
常見問題
GenAI is an indispensable part of the Guru service, and Guru keeps source content protected throughout the entire input/output transaction. Key security features include:
- Only relevant document matches are submitted to the third party LLM; thus ensuring the vast majority of content remains out of the AI workstream (Answers)
- Any content submitted to the third party LLM for processing is immediately removed after the output is returned (“zero day retention”)
- Guru does not use your content to train the LLM in any way; your content remains exclusively yours in a protected enclave
- Our third party AI partner undergoes recurring risk reviews and is bound by a Data Protection Agreement
The program is run by a dedicated infosec leader who works in tandem with executive leadership and subject matter experts to codify procedures and ensure execution.
Guru hires an independent audit firm to conduct an annual SOC 2, Type II audit, which includes not only the Common Criteria, but the Confidentiality and Privacy trust services criteria too.
Yes. We look at changes in the product line, the regulatory environment and the cyber threat. We assign risk scores and ensure executive leadership is routinely engaged in risk mitigation. These steps are verified in the annual SOC 2 audit.
- Guru offers multiple features to synchronize, process, store and make sense of your knowledge sources; inherent to all of these features is your ability to control which knowledge is shared
- Guru will only process what it needs to deliver on its service, and will consequently minimize collection of content and restrict retentions time to the greatest extent possible
- Your content is stored and managed in a highly secure AWS database, separated and protected from other client content by a unique team ID
- Any use of integrators is controlled through highly secure, encrypted API connections
We have a control framework based on the Center for Internet Security Controls, covering a wide compliance spectrum and ensuring we’re focused on the right things. We have nine separate policies that govern the following:
- Security and Privacy Roles
- Risk Management
- Asset Management and Protection
- Data Classification/Handling/Transmission
- Data Recovery and Business Continuity
- User Access Management
- People and Training
- Product Development and Change Management
- Supplier Relationships
By default, Guru staff do not have access to client data. This is reserved for back end administrators with a demonstrated need. These members are approved by the CTO in writing and accesses are reviewed three times annually.
Guru takes your medical privacy and security needs seriously, and while we are prepared to enter into a Business Associate Agreement for HIPAA compliance, we would first ask you to consider the likelihood that the Guru platform will ever consume, process, or store electronic protected health information. If you believe there's a reasonable chance that such personal data will find its way into the system, we are willing to provide a boilerplate BAA as Guru's signed assurance we will abide by the applicable HHS mandates for safeguarding your data.
In addition to AWS, Guru uses some third parties to perform certain components of its operations. Only vendors who have successfully demonstrated sufficient security capabilities and commitments are authorized to support the Guru system.
Any vendor with the potential to access sensitive client data is required to provide an external audit or, at a minimum, submit to a risk interview and demonstrate best security practices. These artifacts are refreshed annually to ensure no lapse in oversight. Moreover, each vendor is required to sign a Data Processing Agreement and contractually commit to data security practices.
Our public facing network is scanned monthly for certificate currency, open ports and protocols and security headers. Our application containers are scanned through AWS prior to deployment to discover and address vulnerabilities.
Yes. The application is routinely pen tested by an outside agency no less than twice per year to reveal common OWASP vulnerabilities. An executive summary is available upon request.
We copy our database daily and save it to a disaster recovery site in an entirely separate region. We run a daily integrity check on that backup to make sure it’s usable if needed. The recovery point objective is 1 hour, with a recovery time objective of 24 hours.
Guru maintains a comprehensive incident classification and response procedure, rehearsing potential incidents twice annually through a formal tabletop exercise. Participants capture lessons learned and constantly strive to make the program better. Though highly unlikely, any data breach would be communicated to a client’s Guru administrator within 24 hours of confirmation.
Security is baked into the coding process, and a number of checks are performed to validate new code prior to deployment. Also, Guru’s developers undergo specialized security training to address common vulnerabilities such as Cross Site Scripting and SQL injection.
Guru fully respects both established and emerging privacy regulations and has created the necessary processes to support the rights of data subjects. Guru offers a Data Protection Agreement and contractually agrees to support any and all emerging privacy regulations as they apply to the service. Third parties are also required to document their security commitments consistent with laws and regulations.
Guru complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Guru has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF. Guru has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in the Guru privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit www.dataprivacyframework.gov
In compliance with the EU-U.S. DPF and the Swiss-U.S. DPF, Guru commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU individuals and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF and the Swiss-U.S. DPF should first contact Guru at: privacy@getguru.com
In compliance with the EU-U.S. DPF and the Swiss-U.S. DPF, Guru commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the Swiss-U.S. DPF to AAA, an alternative dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit AAA for more information or to file a complaint. The services of AAA are provided at no cost to you.
Guru is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC).
Guru is obligated to arbitrate claims and follow the terms as set forth in Annex I of the DPF Principles, provided that an individual has invoked binding arbitration by delivering notice to Guru and following the procedures and subject to conditions set forth in Annex I of Principles
Guru is responsible for the processing of personal information it receives under the DPF Principles and subsequently transfers that information to a third party acting as an agent on its behalf. Consistent with its Privacy Policy ("How We Share Your Information"), Guru shall remain liable under the DPF Principles if third parties process such personal information in a manner inconsistent with the DPF Principles, unless the organization proves that it is not responsible for the event giving rise to the damage.
Yes! Along with this security page, here’s a worksheet outlining Guru’s security and privacy policies.